🔐 CVE Alert

CVE-2026-89175

MEDIUM 5.3

Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.

CWE CWE-602
Vendor kingdom communication associated
Product eh3040
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for kingdom communication associated eh3040

Be the first to know when new medium vulnerabilities affecting kingdom communication associated eh3040 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Kingdom Communication Associated / EH3040
0 < 2.5.0A
Kingdom Communication Associated / EH4200
0 < 2.5.0A
Kingdom Communication Associated / EH1000B
0 < 2.7.0A
Kingdom Communication Associated / EH2070
0 < 2.8.0A

References

NVD ↗ CVE.org ↗ EPSS Data ↗
twcert.org.tw: https://www.twcert.org.tw/tw/cp-132-11198-b8bba-1.html twcert.org.tw: https://www.twcert.org.tw/en/cp-139-11199-38e1e-2.html